Table of Contents
Preface
Part 1: Attack Preparation
1
Mindset and Methodologies
Approach and mindset
The approach
The process
The testing techniques
The baseline competencies
The mindset
Methodologies and frameworks
NIST SP 800-115
Penetration Testing Execution Standard (PTES)
OWASP's WSTG
ISECOM's OSSTMM
The recipe
Summary
Further reading
2
Toolset for Web Attacks and Exploitation
Technical requirements
Operating systems and the tools of the trade
Operating system
Linux
Windows
macOS
Browser
Interception proxy
Python for automating web tasks
Virtualization and containerization systems
VirtualBox
Docker
Summary
Further reading
Part 2: Evergreen Attacks
3
Attacking the Authentication Layer – a SAML Use Case
Technical requirements
Scenario files ...
Get Attacking and Exploiting Modern Web Applications now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.